The business case is usually not security
Most organisations start this because of the service desk queue and the user experience, and argue phishing resistance later, when a mandate arrives. A programme justified on cost gets measured on cost.
Almost nobody eliminates passwords in one move. What works is shrinking the surface where people see one — application by application, population by population — until what remains is small enough to handle deliberately.
None of them is the authentication technology, which is the part that already works.
Most organisations start this because of the service desk queue and the user experience, and argue phishing resistance later, when a mandate arrives. A programme justified on cost gets measured on cost.
The system that cannot be changed, the appliance with a hardcoded login, the third-party portal outside your control. Ignore them and you produce a hybrid state nobody planned.
Enrolling a passkey is easy. Losing the phone is not. The strongest credential in the world is worth what its recovery path is worth, and that path is usually designed last.
A passwordless programme is mostly an enrolment and recovery programme wearing a different name. Plan it that way and the authentication part takes care of itself.
The order matters more than the content. Phase 01 without phase 00 means doing the work once per application; phase 03 without phase 02 means a strong front door and an open window.
Single sign-on ahead of the applications, so authentication stops being a per-application decision. Nothing is passwordless yet; everything is now changeable from one place.
What you stop doingConfiguring authentication separately in each application
Strong, phishing-resistant credentials for the populations and applications that justify them first. Behind the access layer, systems that still expect a password never show one to the user.
What you stop doingAsking people to remember anything for the systems they use daily
Getting credentials onto devices at scale, and defining what happens when a device is lost or replaced — with assurance that matches the credential being restored.
What you stop doingLetting the service desk improvise identity verification over the phone
The legacy application, the shared workstation, the contractor on an unmanaged device. Each gets a deliberate answer rather than a permanent exception nobody revisits.
What you stop doingMaintaining a password policy for the whole organisation because of four systems
A lost phone on a Monday morning is not an edge case, it is a weekly event at any real size. When the answer is a phone call to a service desk that has no way to verify the caller, every passkey in the estate is worth exactly one convincing conversation.
Because recovery is a journey like any other, it can be given its own verification steps, its own thresholds and its own audit trail: a manager approval, a document check, a credential from a wallet, a wait state — chosen deliberately rather than improvised under pressure.
Enrolment, sign-in, step-up and recovery are flows on one canvas. Changing which group gets which method is an edit to a diagram, not a release in every application.
Applications that cannot be modernised sit behind single sign-on. The user authenticates once, strongly, and never meets the password the old system still wants.
What share of authentications are passwordless, for which populations, against which applications — so the programme finishes on evidence rather than on somebody declaring it finished.
There is usually one, and it is usually older than the programme. We'll tell you honestly whether it has to be solved first.
Talk to an expert